Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:40201
HistoryApr 20, 2023 - 4:47 a.m.

Arbitrary Code Injection

2023-04-2004:47:12
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
11
vm2 code injection vulnerability
exception sanitization
handleexception function
attacker
malicious code
sandboxed environment

EPSS

0.002

Percentile

57.3%

vm2 is vulnerable to Code Injection. The vulnerability exists due to lack of exception sanitization in the handleException() function which allows an attacker to inject and execute malicious code and break out of the sandboxed enviroment.